58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-28509 | HIGH 7.5 | rocketsoftware unidata Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire. | 0.3% | — |
| CVE-2023-28302 | HIGH 7.5 | microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 92.6% | — |
| CVE-2023-28300 | HIGH 7.5 | microsoft azure_service_connector Azure Service Connector Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2023-28247 | HIGH 7.5 | microsoft windows_server_2012 Windows Network File System Information Disclosure Vulnerability | 1.6% | — |
| CVE-2023-28241 | HIGH 7.5 | microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-28238 | HIGH 7.5 | microsoft windows_10_1507 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-28234 | HIGH 7.5 | microsoft windows_11_21h2 Windows Secure Channel Denial of Service Vulnerability | 1.7% | — |
| CVE-2023-28233 | HIGH 7.5 | microsoft windows_11_21h2 Windows Secure Channel Denial of Service Vulnerability | 1.7% | — |
| CVE-2023-28232 | HIGH 7.5 | microsoft windows_10_1507 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-28227 | HIGH 7.5 | microsoft windows_10_1507 Windows Bluetooth Driver Remote Code Execution Vulnerability | 6.6% | — |
| CVE-2023-28217 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 1.9% | — |
| CVE-2023-27875 | HIGH 7.5 | ibm aspera_faspex IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Force ID: 249847. | 0.6% | — |
| CVE-2023-27871 | HIGH 7.5 | ibm aspera_faspex IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL query. IBM X-Force ID: 249613. | 0.9% | — |
| CVE-2023-27730 | HIGH 7.5 | f5 njs Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.c. | 0.7% | — |
| CVE-2023-27729 | HIGH 7.5 | f5 njs Nginx NJS v0.7.10 was discovered to contain an illegal memcpy via the function njs_vmcode_return at src/njs_vmcode.c. | 0.7% | — |
| CVE-2023-27728 | HIGH 7.5 | f5 njs Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_vmcode.c. | 0.7% | — |
| CVE-2023-27727 | HIGH 7.5 | f5 njs Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h. | 0.7% | — |
| CVE-2023-27522 | HIGH 7.5 | apache http_server HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client. | 2.1% | — |
| CVE-2023-27378 | HIGH 7.5 | f5 big-ip_access_policy_manager Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached | 0.4% | — |
| CVE-2023-26513 | HIGH 7.5 | apache sling_resource_merger Excessive Iteration vulnerability in Apache Software Foundation Apache Sling Resource Merger.This issue affects Apache Sling Resource Merger: from 1.2.0 before 1.4.2. | 1.5% | — |
| CVE-2023-26464 | HIGH 7.5 | apache log4j ** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages to cause a logging entry involving a specially-crafted (ie, deeply nested) hashmap or hashtable (depending on w | 1.9% | — |
| CVE-2023-26031 | HIGH 7.5 | apache hadoop Relative library resolution in linux container-executor binary in Apache Hadoop 3.3.1-3.3.4 on Linux allows local user to gain root privileges. If the YARN cluster is accepting work from remote (authenticated) users, this MAY permit remote users to gain root p | 2.1% | — |
| CVE-2023-26021 | HIGH 7.5 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service as the server may crash when compiling a specially crafted SQL query using a LIMIT clause. IBM X-Force ID: 247864. | 1.0% | — |
| CVE-2023-25956 | HIGH 7.5 | apache apache-airflow-providers-amazon Generation of Error Message Containing Sensitive Information vulnerability in the Apache Airflow AWS Provider. This issue affects Apache Airflow AWS Provider versions before 7.2.1. | 1.5% | — |
| CVE-2023-25692 | HIGH 7.5 | apache apache-airflow-providers-google Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0. | 1.8% | — |